technology

Google spills the numbers: 170 billion daily phishing mails, tech overtakes finance as prime target

Google’s own security chief just told Business Insider España that out of roughly 300 billion emails the company handles every day, 170 billion are either spam or outright fraud attempts. Read it again: more than half the planet’s inbox traffic is junk, and the fraction that carries a malicious link is growing faster than the filters can adapt.

Voice phishing becomes the new favourite breach lane

According to Mandiant’s M-Trends 2026 dossier, compiled from half a million hours of real incident data gathered throughout 2025, the fastest-rising attack vector is no longer the poisoned attachment. It is a human voice on the line. Criminal call centres now trigger 29 percent of initial compromises worldwide, pushing malware-laden macros to a distant third. The playbook is simple: a fake help-desk caller sweet-talks an employee into running a “diagnostic” script, then immediately hands the session off to a ransomware affiliate. Average hand-off time: 23 seconds. From there, encryption spreads before most security teams finish their first sip of coffee.

Europe is feeling the sting earlier than other regions. While global telemetry shows a 38 percent year-on-year spike in voice-driven breaches, European organisations logged a 54 percent jump, with phishing e-mails still topping the regional chart. The reason is prosaic: GDPR-fuelled data hoarding makes a single successful hit more valuable, so attackers invest extra effort in social engineering.

Tech sector dethrones finance after two-year reign

Tech sector dethrones finance after two-year reign

For the first time since Mandiant began tracking sectors, high-tech companies absorbed 22 percent of all observed intrusions in 2025, edging out financial services at 19 percent. The shift is driven by cloud-hosted intellectual property and a glut of zero-day brokers hungry for source code. Hansen’s team at Google Cloud Security flagged a parallel trend: once inside a SaaS provider, criminals can pivot to hundreds of downstream clients without firing a second exploit. The crown jewel is no longer credit-card data; it is the signing keys that update software your phone trusts.

European defenders, at least, are spotting trouble faster. Sixty percent of last year’s incidents were detected internally, compared with 40 percent the year before. The catch: dwell time still averages 11 days, plenty of room for a nimble intruder to monetise access. Faster detection is useless if the response stops at the alert ticket.

The takeaway is blunt: spam is no longer a nuisance, it is the staging ground for a two-step heist that can vaporise an enterprise before lunch. Filters will miss some lures; humans will answer some calls. Build the chain of controls assuming both will fail, or prepare to star in next year’s report.